The generated raw bundle stays local until you decide to submit it for controlled internal review. Review the handling state, redaction coverage, file list, checksums, and raw inventory before starting intake.
The bundle is created locally under the output path and is not uploaded automatically.
bundle.json identifies collector, schema, and contract versions, cluster context, safety flags, and capability coverage.
Raw inventory is customer-confidential: bundle.json sets contains_sensitive_data=true and handling_state=raw.
upload_safe_after_review permits controlled internal upload only; it never makes raw content customer-shareable.
redaction/coverage.json records raw, redacted, omitted, or not-collected status for every artifact class.
bundle.json and redaction/coverage.json are included in the manifest and checksum chain.
Files left under raw/ remain raw regardless of a conflicting coverage claim.
raw/ contains sanitized Kubernetes metadata without Secret objects or values, environment values, arbitrary annotations, or live traffic capture.
Reports identify checks unavailable because optional collector capabilities were missing.